Impact
The vulnerability resides in the Oracle Warehouse Management component Internal Operations and allows an attacker with low privileges to read any data accessible through the HTTPS interface. The CVSS vector (AV:N/AC:L/PR:L/S:C/C:H) indicates a confidentiality‑only impact, which strongly suggests an improper access‑control weakness. The flaw enables information disclosure of all warehouse data to the attacker, potentially exposing sensitive business information.
Affected Systems
The affected product is Oracle Warehouse Management, part of Oracle E‑Business Suite, targeting the Internal Operations component. Versions 12.2.3 through 12.2.15 are vulnerable. The product is accessed over HTTPS, requiring only network access and no elevated user rights.
Risk and Exploitability
The CVSS 3.1 base score of 7.7 reflects high severity for confidentiality, while the EPSS score of less than 1 % indicates that exploitation is considered unlikely but not impossible. The issue is not listed in the CISA KEV catalog. The likely attack vector involves an attacker with network visibility to the Warehouse Management HTTPS endpoint; because the required privileges are low, the vulnerability is deemed easily actionable for an internal or remotely accessed attacker. The Scope component (S:C) signals that a successful exploit may also affect other Oracle E‑BusinessSuite products.
OpenCVE Enrichment